Skip to main content

Data processing agreement.

The terms under which Keebai processes, on behalf of its customers, the personal data of their end customers. Meets article 15 bis of Chilean Law No. 21.719.

Last updated: July 26, 2026

1. Parties and subject matter

This agreement is entered into between Keebai SpA, Chilean tax ID 78310041-K, domiciled at Av. La Dehesa 1822, Of. 705 (Floor 7), Lo Barnechea, Santiago, Chile ('Keebai'), and the individual or entity contracting the platform ('the Customer'). It forms an integral part of the terms of service and supplements them. Its subject matter is the processing that Keebai carries out, on behalf of and under the instructions of the Customer, of the personal data of the end customers, contacts and other data subjects that the Customer manages through the platform. In the event of conflict between this agreement and the terms of service, this agreement prevails on matters of personal data protection.

2. Roles of the parties

With respect to the personal data that the Customer uploads to or has processed through the platform, the Customer is the data controller and Keebai is the processor, under article 15 bis of Law No. 21.719. The Customer determines the purposes and the essential means of the processing; Keebai carries them out on its behalf. With respect to the Customer's account data, billing, support and platform usage telemetry, Keebai acts as data controller under its privacy policy, and this agreement does not apply.

3. Duration

This agreement takes effect upon acceptance of the terms of service or upon signature of the subscription contract, whichever occurs first, and remains in force for as long as Keebai processes personal data on behalf of the Customer. The secrecy obligations of article 14 bis of Law No. 21.719 and the deletion or return obligations of section 15 survive termination.

4. Purpose and scope of instructions

Keebai processes personal data solely to provide the contracted service, which comprises: receiving, storing and routing messages across the channels the Customer connects; generating responses assisted by language models; maintaining the Customer's record of contacts, conversations, tickets, appointments and transactions; synchronizing with the third-party systems the Customer enables; and delivering reports and analytics on the Customer's own operation. The account configuration, prompts, flows, custom fields and integrations that the Customer defines in the platform constitute documented instructions for all purposes of this agreement. Keebai does not process the Customer's personal data for its own purposes other than the above. In particular, Keebai does not use the content of the Customer's conversations to train general or third-party language models, nor does it disclose it for advertising or commercial purposes. Should Keebai consider that an instruction from the Customer infringes data protection law, it will inform the Customer without delay and may suspend execution of that instruction.

5. Types of personal data processed

Depending on the configuration the Customer chooses, processing may cover: identification and contact data (given name, surname, phone number, email address, channel identifier, identity document where the Customer captures it); communications content (text, images, audio, video and documents exchanged over the connected channels); commercial relationship data (purchase history, carts, orders, payments, support tickets, appointments and bookings, loyalty programme); custom fields freely defined by the Customer; technical and connection data (IP address, device identifier, timestamps, channel metadata); and data inferred by the assistant and retained as long-term memory where the Customer enables that feature. The Customer must not upload sensitive personal data or data of minors to the platform outside the modules expressly enabled for that purpose; if it does, it assumes responsibility for holding the reinforced legal basis required by articles 16 and 16 quáter of Law No. 21.719.

6. Categories of data subjects

The data subjects covered by this processing engagement are the natural persons who interact with the Customer through the channels managed by the platform: end customers and prospects, business contacts, patients or service users where the Customer operates in a healthcare sector, attendees of bookings and appointments, participants in loyalty programmes, and the Customer's employees or collaborators who operate the platform or appear in the content of communications.

7. Keebai's obligations as processor

Keebai undertakes to: (a) process personal data exclusively in accordance with the Customer's documented instructions; (b) ensure that persons authorized to process it have committed to confidentiality; (c) apply the technical and organizational measures of article 14 quinquies described in section 10; (d) not sub-delegate processing to a third party without the Customer's written authorization, which the Customer grants with respect to the sub-processors listed in section 13 and the notification procedure described there; (e) assist the Customer in handling data subject requests under section 12; (f) notify the Customer of security breaches under section 11; (g) make available the information necessary to demonstrate compliance with these obligations; and (h) delete or return the data upon termination of the service under section 15.

8. The Customer's obligations as controller

The Customer represents and warrants that: (a) the personal data it uploads to the platform was lawfully obtained and it holds a valid legal basis under article 12 or 13 of Law No. 21.719 for each purpose it pursues; (b) it has provided data subjects with the transparency information required by article 14 ter, including disclosure that it uses a technology provider to manage its communications; (c) it has obtained express consent where it processes sensitive data and the authorization of the legal representative where it processes data of minors under 14; (d) it is solely responsible for the content of the prompts, flows, custom fields and outbound webhook destination URLs it configures; and (e) it will respond directly to data subjects and to the supervisory authority for compliance with its obligations as controller. The Customer is likewise responsible for managing its own users' access within the platform and for revoking it promptly.

9. Duty of secrecy and support access

Keebai and its personnel are bound by the duty of secrecy of article 14 bis of Law No. 21.719, which survives indefinitely after the contractual relationship ends. Keebai's authorized technical personnel may access the Customer's data only where necessary to operate the platform, diagnose an incident or handle a support request from the Customer itself. Such access is logged and the log is available to the Customer on request. Keebai does not access the content of the Customer's communications for any other purpose.

10. Security measures

Keebai applies technical and organizational measures proportionate to the risk, designed to ensure the confidentiality, integrity, availability and resilience of the processing under article 14 quinquies of Law No. 21.719. These include, among others: encryption in transit via TLS 1.2 or above and encryption at rest of storage; logical segregation of each customer's data and access controls that prevent cross-account access; authentication of internal services and role- and permission-based access control; multi-factor authentication for administrative access; segregation of production and development environments, with anonymization of personal data replicated to the latter; audit logging of operations on personal data, with a defined retention period; cryptographic signature verification of inbound channel webhooks; and periodic review of the effectiveness of these measures. Keebai may update the specific measures provided the level of protection is not reduced.

11. Security breach notification

Keebai will notify the Customer without undue delay, and in any event within 48 hours of becoming aware, of any security breach affecting the personal data processed on its behalf. The notification will be sent to the security contact the Customer has designated in the platform and will describe, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to mitigate it, and a point of contact for further information. Keebai maintains the breach register required by article 14 sexies. It falls to the Customer, as controller, to assess the risk to data subjects' rights and to make any notifications due to the Personal Data Protection Agency and to affected data subjects; Keebai will provide the reasonable assistance the Customer requires for that purpose.

12. Assistance with data subject rights

Data subjects exercise their rights of access, rectification, deletion, objection, blocking, portability and not to be subject to automated decisions before the Customer, who is the controller. Keebai makes available to the Customer the platform functionality needed to handle those requests within the time limits of article 11 of Law No. 21.719, namely 30 calendar days for the general response and 2 business days for blocking. If a data subject addresses a request directly to Keebai, Keebai will forward it to the Customer without delay and will not answer it itself, unless the Customer instructs otherwise.

13. Authorized sub-processors

The Customer expressly authorizes Keebai to sub-contract processing to the providers listed below, imposing on them data protection obligations no less strict than those of this agreement. Infrastructure, always active: Amazon Web Services (compute, object storage, transactional email, notifications and secrets management, us-east-1 region, United States), MongoDB Atlas (database, us-east-1 region, United States) and Google Cloud Platform (push notifications to mobile devices, United States). Language models and embeddings, depending on the model the Customer selects: OpenAI, Anthropic and Google (United States), and Moonshot AI (China) only if the Customer expressly enables that model family. Voice, only if the Customer activates voice channels: Deepgram, ElevenLabs, Google Cloud and OpenAI (United States). Messaging channels, only those the Customer connects: Meta Platforms (WhatsApp, Messenger, Instagram and Lead Ads), Telegram, TikTok, Twilio, Google (Gmail) and Microsoft (Graph). Scheduling, healthcare, commerce and payments, only the integrations the Customer connects: Google Calendar, Microsoft Outlook, AgendaPro, Medilink, Reservo, Dentalink, Shopify, Justo, Mercado Pago and Fintoc. Knowledge base connectors, only those the Customer authorizes via OAuth: Google Drive, Microsoft OneDrive and SharePoint, Notion, Dropbox, Box and Confluence. Ancillary services: Google Maps, Google reCAPTCHA, Tavily, Apple Wallet and Google Wallet. Keebai will inform the Customer at least 30 days in advance of the addition of a new sub-processor, by publishing the update on this page and notifying the registered contact. The Customer may object on reasoned grounds within that period; if the objection prevents provision of the service, either party may terminate the contract with no charge for the unused period.

14. International transfers

Provision of the service involves the transfer of personal data outside Chile, principally to the United States, where the compute and storage infrastructure and most of the sub-processors listed above are located, and potentially to China if the Customer enables Moonshot AI models. The Customer expressly authorizes these transfers. Until the Personal Data Protection Agency issues the model contractual clauses of article 28 of Law No. 21.719, Keebai relies on contractual clauses with each sub-processor that guarantee an adequate level of protection, including obligations of confidentiality, purpose limitation, security and assistance with data subject requests. Keebai will align these instruments with the models approved by the Agency within the period it determines.

15. Deletion or return upon termination

Upon termination of the service for any reason, and at the Customer's election expressed within the following 30 days, Keebai will return the personal data in a structured, commonly used format or delete it. If that period elapses without instruction from the Customer, Keebai will proceed to delete. Deletion covers operational copies and extends to backup copies within their rotation cycle. Keebai may retain data that a legal obligation requires it to keep, solely for that period and that purpose, informing the Customer accordingly.

16. Demonstrating compliance

Keebai will make available to the Customer, on reasonable request and no more than once a year, the information and documentation necessary to demonstrate compliance with the obligations of this agreement, including an up-to-date description of the security measures and any assessment reports it holds. The Customer may request an audit by an independent third party bound by confidentiality, with 30 days' notice, during business hours, without disrupting operations and at the Customer's cost, unless the audit reveals a material breach by Keebai.

17. Liability

Each party is liable for breach of the obligations this agreement imposes on it. Under article 15 bis of Law No. 21.719, a processor that processes data for a purpose other than the one entrusted, discloses it without express authorization or breaches the obligations of the engagement acquires the status of controller and is personally liable for the infringements, and jointly and severally liable with the controller for the damages caused. Keebai accepts that consequence in respect of facts attributable to it. The Customer will hold Keebai harmless against claims from data subjects or the supervisory authority arising from the absence of a legal basis, from breach of the duty to inform, or from the Customer's own unlawful instructions.

18. Amendments, governing law and contact

Keebai may update this agreement to reflect regulatory, infrastructure or sub-processor changes, publishing the current version at this same URL with its update date and notifying the Customer with the notice period stated in section 13 where the change affects sub-processors. This agreement is governed by the laws of the Republic of Chile and disputes are submitted to the ordinary courts of justice seated in the city of Santiago. For questions about this agreement, to request signature in hard copy or to designate the security contact: privacy@keebai.com. To report security incidents: security@keebai.com.